Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

79.697exploits catalogados
36.715CVEs com exploração pública
24.695testados em laboratório
24.466 exploits
Exploit-DB
Mida eFramework 2.9.0 - Back Door Access
CVE-2020-15921webappshardware21 set 2020
Mida eFramework through 2.9.0 has a back door that permits a change of the administrative password and access to restric
28RISCO
abrir
Exploit-DB
BlackCat CMS 1.3.6 - Cross-Site Request Forgery
CVE-2020-25453webappsphp21 set 2020
An issue was discovered in BlackCat CMS before 1.4. There is a CSRF vulnerability (bypass csrf_token) that allows remote
23RISCO
abrir
Exploit-DB
SpamTitan 7.07 - Remote Code Execution (Authenticated)
CVE-2020-11803webappsmultiple18 set 2020
An issue was discovered in Titan SpamTitan 7.07. Improper sanitization of the parameter jaction when interacting with th
23RISCO
abrir
Exploit-DB
SpamTitan 7.07 - Remote Code Execution (Authenticated)
CVE-2020-11699webappsmultiple18 set 2020
An issue was discovered in Titan SpamTitan 7.07. Improper validation of the parameter fname on the page certs-x.php woul
23RISCO
abrir
Exploit-DB
SpamTitan 7.07 - Remote Code Execution (Authenticated)
CVE-2020-11804webappsmultiple18 set 2020
An issue was discovered in Titan SpamTitan 7.07. Due to improper sanitization of the parameter quid, used in the page ma
23RISCO
abrir
Exploit-DB
Mantis Bug Tracker 2.3.0 - Remote Code Execution (Unauthenticated)
CVE-2019-15715webappsphp18 set 2020
MantisBT before 1.3.20 and 2.22.1 allows Post Authentication Command Injection, leading to Remote Code Execution.
35RISCO
abrir
Exploit-DB
Mantis Bug Tracker 2.3.0 - Remote Code Execution (Unauthenticated)
CVE-2017-7615webappsphp18 set 2020
MantisBT through 2.3.0 allows arbitrary password reset and unauthenticated admin access via an empty confirm_hash value
60RISCO
abrir
Exploit-DB
SpamTitan 7.07 - Remote Code Execution (Authenticated)
CVE-2020-11700webappsmultiple18 set 2020
An issue was discovered in Titan SpamTitan 7.07. Improper sanitization of the parameter fname, used on the page certs-x.
23RISCO
abrir
Exploit-DB
Microsoft SQL Server Reporting Services 2016 - Remote Code Execution
CVE-2020-0618CRITICALsob ataqueransomwareremotewindows17 set 2020
A remote code execution vulnerability exists in Microsoft SQL Server Reporting Services when it incorrectly handles page
100RISCO
abrir
Exploit-DB
Piwigo 2.10.1 - Cross Site Scripting
CVE-2020-9467webappsphp16 set 2020
Piwigo 2.10.1 has stored XSS via the file parameter in a /ws.php request because of the pwg.images.setInfo function.
28RISCO
abrir
Exploit-DB
ThinkAdmin 6 - Arbitrarily File Read
CVE-2020-25540webappsphp15 set 2020
ThinkAdmin v6 is affected by a directory traversal vulnerability. An unauthorized attacker can read arbitrarily file on
60RISCO
abrir
Exploit-DBVexDay Proof
CuteNews 2.1.2 - Remote Code Execution
CVE-2019-11447webappsphp10 set 2020
An issue was discovered in CutePHP CuteNews 2.1.2. An attacker can infiltrate the server through the avatar upload proce
35RISCO
abrir
Exploit-DB
ZTE Router F602W - Captcha Bypass
CVE-2020-6862webappshardware10 set 2020
V6.0.10P2T2 and V6.0.10P2T5 of F6x2W product are impacted by Information leak vulnerability. Unauthorized users could lo
23RISCO
abrir
Exploit-DB
ManageEngine Applications Manager 14700 - Remote Code Execution (Authenticated)
CVE-2020-14008webappsjava07 set 2020
Zoho ManageEngine Applications Manager 14710 and before allows an authenticated admin user to upload a vulnerable jar in
35RISCO
abrir
Exploit-DB
Rukovoditel 2.7.1 - Remote Code Execution (2) (Authenticated)
CVE-2020-11819webappsphp02 set 2020
In Rukovoditel 2.5.2, an attacker may inject an arbitrary .php file location instead of a language file and thus achieve
28RISCO
abrir
Exploit-DB
Mida eFramework 2.9.0 - Remote Code Execution
CVE-2020-15920webappsmultiple27 ago 2020
There is an OS Command Injection in Mida eFramework through 2.9.0 that allows an attacker to achieve Remote Code Executi
60RISCO
abrir
Exploit-DBVexDay Proof
Bludit 3.9.2 - Authentication Bruteforce Mitigation Bypass
CVE-2019-17240LOWwebappsphp17 ago 2020
bl-kernel/security.class.php in Bludit 3.9.2 allows attackers to bypass a brute-force protection mechanism by using many
40RISCO
abrir
Exploit-DB
Microsoft SharePoint Server 2019 - Remote Code Execution
CVE-2020-1147HIGHsob ataquewebappsaspx17 ago 2020
A remote code execution vulnerability exists in .NET Framework, Microsoft SharePoint, and Visual Studio when the softwar
100RISCO
abrir
Exploit-DB
Artica Proxy 4.3.0 - Authentication Bypass
CVE-2020-17506webappshardware13 ago 2020
Artica Web Proxy 4.30.00000000 allows remote attacker to bypass privilege detection and gain web backend administrator p
60RISCO
abrir
Exploit-DB
ACTi NVR3 Standard or Professional Server 3.0.12.42 - Denial of Service (PoC)
CVE-2020-15956doswindows05 ago 2020
ActiveMediaServer.exe in ACTi NVR3 Standard Server 3.0.12.42 allows remote unauthenticated attackers to trigger a buffer
28RISCO
abrir
Exploit-DB
Pi-hole 4.3.2 - Remote Code Execution (Authenticated)
CVE-2020-8816CRITICALsob ataquewebappspython04 ago 2020
Pi-hole Web v4.3.2 (aka AdminLTE) allows Remote Code Execution by privileged dashboard users via a crafted DHCP static l
100RISCO
abrir
Exploit-DB
Cisco Adaptive Security Appliance Software 9.7 - Unauthenticated Arbitrary File Deletion
CVE-2020-3187CRITICALwebappshardware29 jul 2020
Cisco Adaptive Security Appliance Software and Firepower Threat Defense Software Web Services Path Traversal Vulnerability
85RISCO
abrir
Exploit-DB
Wordpress Plugin Maintenance Mode by SeedProd 5.1.1 - Persistent Cross-Site Scripting
CVE-2020-15038webappsphp29 jul 2020
The SeedProd coming-soon plugin before 5.1.1 for WordPress allows XSS.
23RISCO
abrir
Exploit-DB
Cisco Adaptive Security Appliance Software 9.11 - Local File Inclusion
CVE-2020-3452HIGHsob ataquewebappshardware28 jul 2020
Cisco Adaptive Security Appliance Software and Firepower Threat Defense Software Web Services Read-Only Path Traversal Vulnerability
100RISCO
abrir
Exploit-DB
Bludit 3.9.2 - Directory Traversal
CVE-2019-16113webappsmultiple26 jul 2020
Bludit 3.9.2 allows remote code execution via bl-kernel/ajax/upload-images.php because PHP code can be entered with a .j
60RISCO
abrir
Exploit-DB
pfSense 2.4.4-p3 - Cross-Site Request Forgery
CVE-2019-16667webappsphp26 jul 2020
diag_command.php in pfSense 2.4.4-p3 allows CSRF via the txtCommand or txtRecallBuffer field, as demonstrated by executi
35RISCO
abrir
Exploit-DB
Rails 5.0.1 - Remote Code Execution
CVE-2020-8163webappsruby26 jul 2020
The is a code injection vulnerability in versions of Rails prior to 5.0.1 that wouldallow an attacker who controlled the
60RISCO
abrir
Exploit-DB
F5 Big-IP 13.1.3 Build 0.0.6 - Local File Inclusion
CVE-2020-5902CRITICALsob ataqueransomwarewebappshardware26 jul 2020
In BIG-IP versions 15.0.0-15.1.0.3, 14.1.0-14.1.2.5, 13.1.0-13.1.3.3, 12.1.0-12.1.5.1, and 11.6.1-11.6.5.1, the Traffic
100RISCO
abrir
Exploit-DB
Bio Star 2.8.2 - Local File Inclusion
CVE-2020-15050webappsmultiple26 jul 2020
An issue was discovered in the Video Extension in Suprema BioStar 2 before 2.8.2. Remote attackers can read arbitrary fi
50RISCO
abrir
Exploit-DB
INNEO Startup TOOLS 2018 M040 13.0.70.3804 - Remote Code Execution
CVE-2020-15492webappsmultiple26 jul 2020
An issue was discovered in INNEO Startup TOOLS 2017 M021 12.0.66.3784 through 2018 M040 13.0.70.3804. The sut_srv.exe we
28RISCO
abrir
anteriorpágina 46 / 816próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.